← Retour aux CVEs
CVE-2020-11497
HIGH7.5
Description
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
Details CVE
Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie8/26/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
woocommerce:nab_transact
Faiblesses (CWE)
CWE-354
References
http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html(cve@mitre.org)
http://seclists.org/fulldisclosure/2020/Aug/13(cve@mitre.org)
http://seclists.org/fulldisclosure/2020/Aug/13(cve@mitre.org)
http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2020/Aug/13(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2020/Aug/13(af854a3a-2127-422b-91ae-364da2661108)
https://www.themissinglink.com.au/security-advisories-cve-2020-11497(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.